zoning-analysis-uruguay

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted GIS JSON data from users to extract lot attributes which then drive the analysis workflow. The lack of explicit boundary markers or input sanitization for these fields creates a surface for indirect prompt injection.\n- Ingestion points: GIS JSON data attributes (e.g., nomloccat, nummancat) in SKILL.md.\n- Boundary markers: Absent.\n- Capability inventory: The agent has access to Write, Bash, and WebFetch tools.\n- Sanitization: No data validation or sanitization is described for the extracted attributes.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 12:42 PM
Security Audit — agent-trust-hub — zoning-analysis-uruguay